CVE-2021-3271
Summary
| CVE | CVE-2021-3271 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-18 19:15:00 UTC |
| Updated | 2021-02-24 14:45:00 UTC |
| Description | PressBooks 5.17.3 contains a cross-site scripting (XSS). Stored XSS can be submitted via the Book Info's Long Description Body, and all actions to open or preview the books page will result in the triggering the stored XSS. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Pressbooks | Pressbooks | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2021-3271 Pressbooks Stored Cross Site Scripting Proof of Concept | GoSecure | MISC | www.gosecure.net | Exploit, Third Party Advisory |
| Fix XSS security vulnerability by arzola · Pull Request #2072 · pressbooks/pressbooks · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| GitHub - pressbooks/pressbooks: Open publishing. Open web. Open source. | MISC | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.